Payment GatewaysKora

Kora Payment Gateway Integration

Connect Kora to PayLexer to accept cards, bank transfers, mobile money and EFTs across Nigeria, Kenya, Ghana, South Africa and other African markets.

Kora is a pan-African payments infrastructure company, founded in Nigeria and known previously as Korapay. Through a single integration, Kora lets merchants collect the payment methods African shoppers actually use - cards, bank transfers, mobile money, instant EFTs and virtual bank accounts - across Nigeria, Kenya, Ghana, South Africa and several other markets.

  • Supported Regions (Merchant Accounts): Africa (including Nigeria, Kenya, Ghana, South Africa, Egypt, Cameroon, Ivory Coast, Tanzania and Zambia) - view full list
  • Supported Currencies: NGN, KES, GHS, ZAR, USD, EGP, XAF, XOF, TZS - view full list

Supported Features

  • Hosted checkout that redirects shoppers to Kora's secure payment page
  • Card payments, bank transfers, mobile money, instant EFTs and virtual bank accounts
  • Full refunds
  • Partial refunds
  • Real-time webhook notifications for payments and refunds, secured with HMAC-SHA256 signatures
  • Automatic recovery of refunds issued directly inside the Kora dashboard
  • Separate test and live credentials for safe testing

Kora does not support subscriptions or recurring billing in PayLexer. Kora's scheduled billing is limited to Nigerian bank direct debit, which requires the customer's bank account details and sits outside the checkout flow, so only one-time payments are available.

Before You Start

Make sure you have:

Looking for a different payment processor? View all supported gateways →

Configuring Kora

You need a Secret Key and Public Key from Kora for this integration.

Getting API Credentials

Log in to Kora

Sign in to your Kora dashboard.

Choose your environment

Switch the dashboard to Test Mode to collect sandbox credentials, or leave it in live mode to collect production credentials. Kora issues a completely different set of keys for each, so collect them one environment at a time.

Open API Configuration

Go to Settings → Product & Payment Settings → API Configuration. You will see an API Keys section containing your Public Key and Secret Key.

Copy both keys

Copy the Public Key and the Secret Key using the copy icon beside each value. Keep the Secret Key private - it authorises payments and refunds on your account.

The Encryption Key shown on the same screen is not required. It is only used for direct card integrations, and PayLexer uses Kora's hosted checkout, so card details are entered on Kora's own page and never reach PayLexer.

Adding Credentials to PayLexer

Open PayLexer Dashboard

Log in to your PayLexer dashboard and navigate to Payment Gateways → Kora.

Enter your credentials

Paste the Secret Key and Public Key you copied from Kora into the corresponding fields.

Understanding Live/Production and Sandbox Settings:

EnvironmentPurpose
Live / ProductionUsed for real transactions.
Test / SandboxUsed for testing only. No real money is processed.

How PayLexer selects credentials:

  • Debug/Test mode ON → Test credentials are used
  • Debug/Test mode OFF → Live credentials are used

Test and save

Click Save to save your configuration and verify your credentials. Click Verify Connection to test the connection.

Configuring Webhooks (Mandatory)

Webhooks enable real-time payment updates and significantly improve reliability.

Benefits of Webhooks:

  • Instant payment status updates
  • Automatic refund processing
  • Dispute notifications

Copy your PayLexer webhook URL

On the Payment Gateways → Kora page in PayLexer, copy the Webhook URL. It is generated for your account and shown as a read-only field.

Open Notification URLs in Kora

In your Kora dashboard, go to Settings → Product & Payment Settings → API Configuration and scroll to the Notification URLs section.

Paste and save the URL

Paste the PayLexer webhook URL into the notification URL field and save.

Kora uses a single notification URL for your whole account rather than one per payment, and payment confirmations are delivered to it. If this is left blank, orders may stay pending even after a customer has paid.

There is no separate webhook secret to enter. Kora signs every notification with your Secret Key, so saving your credentials is all PayLexer needs to verify that a notification genuinely came from Kora.

Integrate Kora to Your Website

If you have already added and configured your site, you can enable Kora in your existing setup.

Go to Websites

Navigate to Websites in your PayLexer dashboard.

Edit your website

Click the Edit Icon of your added website.

Enable Kora

Click the checkbox to enable Kora for the website.

If you haven't added a website yet, Continue to Add Your Website →

Troubleshooting

Best Practices

  • Test in sandbox before enabling production, using your Kora test keys with Debug/Test mode ON
  • Save your PayLexer webhook URL in Kora's Notification URLs before taking live payments
  • Enable the currencies and payment channels you plan to sell with in your Kora dashboard first
  • Keep order totals above Kora's minimum amount, especially when testing
  • Use real customer email addresses, as Kora rejects reserved domains such as .local
  • Keep your Secret Key private and rotate it in Kora if you suspect it has been exposed
  • Reconcile your PayLexer orders against your Kora dashboard periodically

FAQs

Still Have Questions?